CVE-2026-70124
massOut-of-Bounds Read in Windows DHCP Server Enables Unauthenticated Info Disclosure
CVE-2026-70124 is an out-of-bounds read (CWE-125) in the Windows DHCP Server service. A remote, unauthenticated attacker can likely trigger it by sending crafted DHCP network traffic to a system running the DHCP Server role (DHCP servers listen on UDP 67), causing the service to read beyond the bounds of an allocated buffer. The impact is disclosure of memory contents on the affected host: the CVSS vector scores confidentiality as high with no integrity or availability impact, and no privileges or user interaction are required, so there is no indication of remote code execution. Affected organizations are those running Windows 10 1607/1809 or Windows Server 2012/2016/2019/2022/2025 with the DHCP Server service enabled, which in practice means Windows Server hosts acting as DHCP servers on internal enterprise networks. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates roughly a 0.8% probability of exploitation in the next 30 days.
What to do: Inventory Windows hosts running the DHCP Server role/service and apply Microsoft's security update for CVE-2026-70124 when released, prioritizing DHCP servers reachable from untrusted or unmanaged network segments; as an interim mitigation, restrict UDP 67 access to DHCP servers with network ACLs. Note that Windows 10 client systems are only affected if the DHCP Server service has been enabled, which is uncommon, and treat the confidentiality-only impact as potentially exposing sensitive memory contents on the server.
| microsoft windows 10 1607 | — |
| microsoft windows 10 1809 | — |
| microsoft windows server 2012 | — |
| microsoft windows server 2016 | — |
| microsoft windows server 2019 | — |
| microsoft windows server 2022 | — |
| microsoft windows server 2025 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.